SUSPICIOUS — givapomezamew.pdf
SUSPICIOUS — givapomezamew.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
f1a6129b5e437f9681939d25c1059cfebc9b531f5ccde164d11e02c9aa7c4b3d - SHA-1:
19e78fd535f66a6c3708355364527853376334aa - MD5:
089cf3d1440b8d437263bbe0b1aee12b - ssdeep:
1536:ZGFXp00k+n7jh1EpvI0jW8bGV8fdJ911mH:sFXp0j+n7N1UvIoGV8fT910 - TLSH:
T168348EF71197FC8C3A8BAB07EDE20558A149C28E6037DBA054D9776CC0BC6AD3E11961 - Submitted as: givapomezamew.pdf
- File type: pdf · Size: 53143 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=lego%20marvel%20superheroes%202%20wakanda, https://uploads.strikinglycdn.com/files/cddaead3-731a-4ac6-a626-59cff65e5c26/rixavuzigivuxa.pdf, https://uploads.strikinglycdn.com/files/c3e82581-fa9c-4fb2-8e53-5822d8332f19/gulugufotepani.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=lego%20marvel%20superheroes%202%20wakanda
- https://uploads.strikinglycdn.com/files/cddaead3-731a-4ac6-a626-59cff65e5c26/rixavuzigivuxa.pdf
- https://uploads.strikinglycdn.com/files/c3e82581-fa9c-4fb2-8e53-5822d8332f19/gulugufotepani.pdf
- https://uploads.strikinglycdn.com/files/aed3b191-51ec-4ef0-a31e-3502597ab10f/kesibotegula.pdf
- https://uploads.strikinglycdn.com/files/69bfbf30-0629-42e2-af63-a8cace1f5bca/jebikupagutaju.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/punedatotum-vodokubokex-lajifut-zonujasus.pdf
- https://cdn.shopify.com/s/files/1/0433/1290/6405/files/bidafo.pdf
- https://cdn.shopify.com/s/files/1/0481/5886/7607/files/playstation_3_power_cord.pdf
- https://cdn.shopify.com/s/files/1/0501/7442/7296/files/78766303158.pdf
- https://cdn.shopify.com/s/files/1/0484/7121/2193/files/scientific_method_quiz.pdf
- https://cdn.shopify.com/s/files/1/0484/2740/1368/files/75376662716.pdf
- https://cdn.shopify.com/s/files/1/0435/5109/6984/files/rezixifawutawo.pdf
- https://cdn.shopify.com/s/files/1/0434/0377/2056/files/82282108305.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f8909313a6aa.pdf
- https://cdn-cms.f-static.net/uploads/4375702/normal_5f8b06c00416e.pdf
- https://cdn-cms.f-static.net/uploads/4383160/normal_5f8cbb9d7ab29.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f889bcb8c015.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f88782f9126a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- nurekagenarufab.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report